Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns Information Security Magazine 6 days 19 hours ago A quarter of victims of deepfake attacks have lost over $1m. CISOs worry that boardrooms don’t understand the threat
MCP Is Creating Major Governance Gaps, Researchers Warn Information Security Magazine 6 days 23 hours ago Ox Security found security shortcomings in analysis of over 15,000 MCP servers
Citrix Patches Critical Zero Days Under Active Exploitation Information Security Magazine 1 week ago Citrix has confirmed exploitation of two critical zero-day RCE bugs
Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk Information Security Magazine 1 week 2 days ago The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration
CISA Unveils Election Security Plan Ahead of 2026 Midterms Information Security Magazine 1 week 2 days ago The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines
RemControl Banking Trojan Gives Attackers Remote Control of Android Devices Information Security Magazine 1 week 2 days ago The newly-discovered trojan abuses the Android Accessibility Service to gain control over victim devices and collect sensitive banking credentials
Researchers Identify AliExpress Phishing Domains Before Registration Information Security Magazine 1 week 3 days ago EfficientIP says it flagged AliExpress phishing domains before they were registered
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims Information Security Magazine 1 week 3 days ago Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims
CISA Charts New "Quality Era" for Global CVE Program Information Security Magazine 1 week 3 days ago CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit Information Security Magazine 1 week 3 days ago Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy
OpenAI Agent Hacks Australian Medicare Portal Information Security Magazine 1 week 3 days ago Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026
Over 75% of Organizations Experience Microsoft 365 Governance Issues Information Security Magazine 1 week 3 days ago ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows
Data Overtakes Skills as Top Threat Hunting Challenge, SANS Study Finds Information Security Magazine 1 week 4 days ago SANS Institute report claims data rather than skills is now the main hurdle for threat hunters
Hundreds of Leaked GitHub App Keys Still Authenticate Information Security Magazine 1 week 4 days ago GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods Information Security Magazine 1 week 4 days ago Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Ransomware Attacks Reach Record High for 2026 Information Security Magazine 1 week 4 days ago A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day Information Security Magazine 1 week 4 days ago Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response Information Security Magazine 1 week 5 days ago The EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidents
North Korean Attackers Hit 30,000 Devices and Steal $10.7m Information Security Magazine 1 week 5 days ago WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds Information Security Magazine 1 week 5 days ago A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure